2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-35660MEDIUM5.4Cross Site Scripting (XSS) in Monica before 2.19.1 via the journal page.
CVE-2020-28124MEDIUM5.4Cross Site Scripting (XSS) in LavaLite 5.8.0 via the Address field.
CVE-2020-35419MEDIUM6.1Cross Site Scripting (XSS) in Group Office CRM 6.4.196 via the SET_LANGUAGE parameter.
CVE-2020-35418MEDIUM5.4Cross Site Scripting (XSS) in the contact page of Group Office CRM 6.4.196 by uploading a crafted svg file.
CVE-2020-29593MEDIUM5.4An issue was discovered in Orchard before 1.10. The Media Settings Allowed File Types list field allows an attacker to a...
CVE-2020-21088MEDIUM4.8Cross Site Scripting (XSS) in X2engine X2CRM v7.1 and older allows remote attackers to obtain sensitive information by i...
CVE-2020-21087MEDIUM6.1Cross Site Scripting (XSS) in X2Engine X2CRM v6.9 and older allows remote attackers to execute arbitrary code by injecti...
CVE-2020-36322MEDIUM5.5An issue was discovered in the FUSE filesystem implementation in the Linux kernel before 5.10.6, aka CID-5d069dbe8aaf. f...
CVE-2020-28590MEDIUM6.5An out-of-bounds read vulnerability exists in the Obj File TriangleMesh::TriangleMesh() functionality of Slic3r libslic3...
CVE-2020-4964MEDIUM4.3IBM Jazz Team Server products contain an undisclosed vulnerability that could allow an authenticated user to present a c...
CVE-2020-4920MEDIUM5.4IBM Jazz Team Server products are vulnerable to stored cross-site scripting. This vulnerability allows users to embed ar...
CVE-2020-7924MEDIUM6.5Usage of specific command line parameter in MongoDB Tools which was originally intended to just skip hostname checks, ma...
CVE-2020-15734MEDIUM5.5An Origin Validation Error vulnerability in Bitdefender Safepay allows an attacker to manipulate the browser's file uplo...
CVE-2020-15942MEDIUM6.5An information disclosure vulnerability in Web Vulnerability Scan profile of Fortinet's FortiWeb version 6.2.x below 6.2...
CVE-2020-23762MEDIUM5.4Cross Site Scripting (XSS) vulnerability in the Larsens Calender plugin Version <= 1.2 for WordPress allows remote attac...
CVE-2020-23761MEDIUM6.1Cross Site Scripting (XSS) vulnerability in subrion CMS Version <= 4.2.1 allows remote attackers to execute arbitrary we...
CVE-2020-36287MEDIUM5.3The dashboard gadgets preference resource of the Atlassian gadgets plugin used in Jira Server and Jira Data Center befor...
CVE-2020-14106MEDIUM5.5The application in the mobile phone can unauthorized access to the list of running processes in the mobile phone, Xiaomi...
CVE-2020-14103MEDIUM5.5The application in the mobile phone can read the SNO information of the device, Xiaomi 10 MIUI < 2020.01.15.
CVE-2020-36316MEDIUM5.5In RELIC before 2021-04-03, there is a buffer overflow in PKCS#1 v1.5 signature verification because garbage bytes can b...
CVE-2020-36315MEDIUM5.3In RELIC before 2020-08-01, RSA PKCS#1 v1.5 signature forgery can occur because certain checks of the padding (and of th...
CVE-2020-24137MEDIUM5.3Directory traversal vulnerability in Wcms 0.3.2 allows an attacker to read arbitrary files on the server that is running...
CVE-2020-24135MEDIUM6.1A Reflected Cross Site Scripting (XSS) Vulnerability was discovered in Wcms 0.3.2, which allows remote attackers to inje...
CVE-2020-24138MEDIUM6.1Cross Site Scripting (XSS) vulnerability in wcms 0.3.2 allows remote attackers to inject arbitrary web script and HTML v...
CVE-2020-11252MEDIUM5.5Trustzone initialization code will disable xPU`s when memory dumps are enabled and lead to information disclosure in Sna...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now